EC-Council CTIA Module 5.1 Practice Test 002

This practice test covers Module 5 (Data Analysis) Sub-module 1 (Data Analysis).

These questions are inspired by the EC-Council CTIA exam and are designed to help you test your knowledge of cyber threat intelligence, threats and frameworks, and other related topics. Some questions require multiple correct answers.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the skills and knowledge tested in the CTIA exam.

Note: CTIA is a registered trademark of EC-Council. This content is not affiliated with or endorsed by EC-Council.

To choose CTIA practice tests based on specific modules and sub-modules, click that link

EC-Council CTIA Module 5.1 Practice Test 002
10 questions • Single best answer
Question 1
An analyst at a healthcare provider examines processed indicators to identify patterns, draw conclusions, and support security decisions. This stage transforms structured information into meaningful findings within the intelligence lifecycle. Which CTI process is being described?
    Question 2
    A SOC analyst at a regional bank counts malware detections and computes numerical trends across thousands of events to derive measurable statistics. The output is expressed entirely in numbers. Which analysis type relies on numerical and measurable data?
      Question 3
      A threat analyst at an MSSP lists several possible explanations for an intrusion and systematically evaluates evidence to disprove each one. The method favors the explanation with the least contradicting evidence. Which technique is being applied?
        Question 4
        A government CTI team must weigh dozens of hypotheses collaboratively using software that scales the traditional matrix approach for large groups. They need a more rigorous, tool-supported variant of the classic method. Which approach fits?
          Question 5
          An analyst at a cloud security provider applies mathematical formulas and probability models to large datasets to uncover correlations and trends among threat events. The work is grounded in measurable computation. Which approach is being used?
            Question 6
            A CTI analyst studies adversary motivations, intent, and contextual narratives that cannot be reduced to numbers. The findings rely on interpretation rather than measurement. Which analysis type is this?
              Question 7
              After processing collected feeds, a threat hunting team reviews the data to answer intelligence requirements and support defensive decisions. The team focuses on the end purpose of this lifecycle stage. What is its primary goal?
                Question 8
                An intelligence lead notices analysts favoring their first conclusion and ignoring disconfirming evidence. She introduces structured analytic techniques to counter this tendency. What is the main benefit of these techniques?
                  Question 9
                  A CTI team at a critical infrastructure operator models historical attack data to forecast likely future adversary actions. The output estimates what may happen next. Which analysis type is this?
                    Question 10
                    An analyst completes an evidence matrix weighing each candidate explanation against the available data. To reach a defensible conclusion, the analyst must decide which one to accept. Which should be selected?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top